The data traced end to end
Actual flows mapped from collection to model — the factual foundation every privacy position stands or falls on.
AI privacy and safety exposure counsel from Aun & Co.: data-protection duties, safety-relevant deployments and incident posture for businesses using AI.
The moment AI systems process personal data, two exposure lines converge: privacy law — Israel's Protection of Privacy framework and, for many businesses, European rules reaching them through customers and markets — and safety, where automated outputs shape decisions about real people. Consent gathered for one purpose feeding models built for another, profiles generated without a lawful basis, incidents no one is prepared to notify: these are the standing failure modes. The firm maps the exposure, closes the gaps, and prepares the incident posture before the incident.
The firm traces the data, not the marketing: what personal information actually enters each system, under what basis it was collected, what the vendor's terms do with it, and where it travels. Deployments touching people — scoring, filtering, automated decisions — get a second pass for the duties those functions engage. The output is dual: a compliance gap list sequenced by enforcement risk, and an incident playbook, because privacy failures are judged largely on the response.
Actual flows mapped from collection to model — the factual foundation every privacy position stands or falls on.
Automated decisions about individuals reviewed against the duties they trigger, before a complaint or regulator does the review instead.
A playbook with roles, clocks and drafted notifications — because the legal cost of a breach is set mostly in its first hours.
A typical engagement: a business using AI tools across marketing and HR discovers, through the mapping, that employee data collected for payroll feeds an analytics model under no valid basis. The flow is restructured, the consents corrected, and an incident playbook installed — ahead of any complaint.
Described in abbreviated, anonymised form to preserve client confidentiality.

Yes — Israel's Protection of Privacy framework governs personal data regardless of the technology processing it, including registration, security and use-limitation duties. AI changes the risk profile and the scale, not the applicability.
Only within the basis on which it was collected — purpose limitation is the controlling principle. Data gathered for service delivery does not automatically extend to model training or profiling; the gap between collected-for and used-for is where enforcement concentrates.
Containment, preservation and assessment in parallel: stop the flow, freeze the evidence, and establish what data and whose. Notification duties run on short clocks once thresholds are met — which is why the playbook, roles and draft notices must exist before the incident does.